Analysis · curated 20 Sep 2026

The AI Agent Question SR 26-2 Leaves Your Bank to Answer

Coverage timeline

20 Sep 2026curity.io

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Agentic AI in banking raises the risk of over-permissioned autonomous agents taking unauthorized actions (like moving funds), so defenders need explicit authorization, least privilege, and rapid revocation controls to trace and contain compromised agents.

Curity's blog discusses how banks should handle authorization and identity for agentic AI following SR 26-2, the April 2026 Federal Reserve/OCC/FDIC guidance that excludes generative and agentic AI from model risk management rules while leaving governance to institutions. It argues that common shortcuts—long-lived service accounts or handing agents a user's own token—obscure which agent acted under whose authority, and advocates zero-trust, task-scoped delegation with fast revocation for compromised agents.